EU AI Act after August 2026: what fashion companies must comply with now
Most of the AI Act has applied since 2 August 2026, but the AI Omnibus pushed high-risk rules to December 2027. A dated checklist for fashion brands and retailers.
KEY TAKEAWAYS Summary by the editors
- The EU AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and most of its provisions have applied since 2 August 2026.
- Prohibited practices and the AI literacy duty have applied since 2 February 2025, and obligations for general-purpose AI models since 2 August 2025.
- The AI Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and moved the rules for Annex III high-risk systems, such as AI used in recruitment, to 2 December 2027.
- Article 50 transparency duties, including chatbot disclosure and deepfake labelling, apply from 2 August 2026, while providers of generative systems already on the market have until 2 December 2026 to add machine-readable marking.
- Breaching prohibited-practice rules can cost up to EUR 35 million or 7% of worldwide turnover, and breaching transparency or deployer obligations up to EUR 15 million or 3%.
Since 2 August 2026 the EU AI Act applies in large part, so a fashion company using AI in the EU must already respect the bans on prohibited practices, support AI literacy among staff and meet the Article 50 transparency rules for chatbots and synthetic content. The heaviest obligations, those for high-risk systems such as AI used in hiring, were postponed by the AI Omnibus to 2 December 2027. The sensible reading for fashion is: less urgency on high-risk paperwork, no delay on transparency and governance.
What changed in August 2026?
The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and phases in over several years. According to the European Commission, prohibited practices and AI literacy obligations applied from 2 February 2025, governance rules and the duties for general-purpose AI (GPAI) models from 2 August 2025, and the Act became broadly applicable on 2 August 2026, including the transparency rules and enforcement by the AI Office and national authorities.
In parallel, the EU amended the Act. The AI Omnibus, published as Regulation (EU) 2026/1744 in the Official Journal on 24 July 2026, entered into force on 27 July 2026, according to White & Case. It postponed Chapter III high-risk requirements, added new prohibitions on AI that generates child sexual abuse material or non-consensual intimate imagery, and extended simplified documentation from SMEs to small mid-cap companies.
| Date | What applies | Typical fashion touchpoint |
|---|---|---|
| 2 Feb 2025 | Prohibited practices; AI literacy (Article 4) | Manipulative design, workplace emotion recognition, staff training |
| 2 Aug 2025 | Obligations for providers of GPAI models | Mainly model developers; brands are usually downstream users |
| 2 Aug 2026 | Most of the Act, including Article 50 transparency and national enforcement | Chatbots, AI imagery, deepfake disclosure |
| 2 Dec 2026 | Marking deadline for generative systems already on the market; new nudification and CSAM bans | Image generation tools used in content production |
| 2 Dec 2027 | High-risk rules for Annex III systems | Recruitment and worker management tools |
| 2 Aug 2028 | High-risk rules for AI in regulated products (Annex I) | Rare in apparel; relevant for some wearables or machinery |
Which AI uses in fashion fall under which risk level?
The Act sorts AI by risk. The Commission notes that most AI systems in use fall into the minimal-risk category with no specific rules. For a typical brand or retailer, that covers much of demand forecasting, assortment planning, product data enrichment and search ranking. The obligations bite in three places: practices that are banned, uses listed as high-risk, and systems that trigger transparency duties.
- Prohibited: practices banned under Article 5, such as social scoring, untargeted scraping of facial images and emotion recognition in the workplace.
- High-risk (Annex III): uses in areas such as employment (for example recruitment and worker management) and access to essential services, which face risk management, data quality, documentation and human oversight duties.
- Transparency (Article 50): customer-facing chatbots, AI-generated images, video, audio and text, deepfakes, and emotion recognition or biometric categorisation shown to customers.
- Minimal risk: most planning, forecasting and internal productivity tools, subject to GDPR and general law.

What should be on the checklist today?
The following list reflects obligations that already apply or will apply within months. It assumes the company is mostly a deployer (a user of AI systems built by others), which is the usual position for brands and retailers.
- Build an AI inventory. List every AI system in use, including features embedded in e-commerce, PIM, HR and marketing software, with an owner and an intended purpose.
- Screen for prohibited practices. Check personalisation, pricing and persuasion features against the Article 5 bans, and confirm no workplace tool infers employees' emotions.
- Document AI literacy measures. The Omnibus softened Article 4 to a duty to take measures that support AI literacy; the Commission says an internal record of training is sufficient and no certificate is needed.
- Disclose chatbots. Customers must be told they are interacting with AI, at the latest at first interaction, unless it is obvious.
- Label deepfakes. Images or video that resemble real people, places or events and could appear authentic must be disclosed by the deployer, with a lighter regime for evidently creative work.
- Ask vendors about marking. Providers of generative tools must mark outputs in a machine-readable way; systems already on the market have until 2 December 2026.
- Map high-risk candidates. Identify HR and credit-related systems now, because the high-risk obligations, including human oversight, arrive on 2 December 2027.
- Assign accountability. Name an executive owner and decide who signs off new AI use cases.
When does a fashion brand become an AI provider?
Most brands buy AI. But under Article 25 a deployer becomes a provider of a high-risk system if it puts its own name or trademark on it, makes a substantial modification, or changes the intended purpose of a system so that it becomes high-risk. A retailer that adapts a general-purpose model into its own candidate-screening tool, for example, would take on provider obligations from December 2027.
How high are the penalties?
Article 99 sets maximum fines. Breaches of the prohibitions can be fined up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. Breaches of other obligations, explicitly including deployer duties under Article 26 and transparency duties under Article 50, can reach EUR 15 million or 3%. Supplying incorrect or misleading information to authorities can cost up to EUR 7.5 million or 1%. For SMEs the lower of the two amounts applies. Fines are set nationally and must be proportionate, so these are ceilings, not tariffs.

What should leadership decide before 2027?
The postponement gives fashion companies time to fix foundations rather than produce paperwork. Three decisions matter most: who owns AI governance (often a joint brief between legal, HR, IT and e-commerce), which use cases the company will not pursue (for example automated scoring of staff), and how vendor contracts will allocate documentation and logging duties. Companies that already run GDPR data protection impact assessments can extend that process instead of building a parallel one.
The practical limit is information. Much of what a deployer must know, from training data to marking methods, sits with software providers. That is why the inventory and the vendor questionnaire are the two documents worth starting this quarter.
Frequently asked questions
Does the EU AI Act apply to fashion companies?
Yes, if they place AI systems on the EU market or use them in the EU. Most fashion uses are minimal risk, but chatbots, AI imagery, HR tools and credit scoring trigger specific duties.
Was the AI Act delayed in 2026?
Partly. The AI Omnibus, in force since 27 July 2026, moved Annex III high-risk rules to 2 December 2027 and product-related high-risk rules to 2 August 2028. Prohibitions, AI literacy and most Article 50 transparency duties were not delayed.
What are the AI Act fines?
Up to EUR 35 million or 7% of worldwide turnover for prohibited practices, and up to EUR 15 million or 3% for breaches of other obligations such as deployer or transparency duties. SMEs face the lower of the two amounts.
Is AI used for demand forecasting high-risk?
Not under the Act's Annex III list, which focuses on areas such as employment, credit, education and biometrics. Forecasting and assortment tools are generally minimal risk, though GDPR still applies if they process personal data.
One edition every weekday morning. Read in five minutes. Free for industry professionals.
SOURCES
- European Commission: AI Act, regulatory framework for AI
- White & Case: EU AI Omnibus enters into force, amending the AI Act
- artificialintelligenceact.eu: Article 99, Penalties
- European Commission: AI literacy, questions and answers
- artificialintelligenceact.eu: Article 25, Responsibilities along the AI value chain


